Live data from Hacker News

Multiple Russia-aligned threat actors actively targeting Signal Messenger

cloud.google.com

91–100 of 329 posts

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#91

Earlier quoted context omitted.

Yeah, this just gave me the last nudge I needed to give Signal a go.

[flagged]

I'm a big signal user yet skeptical that it's not directly involved with intelligence agencies. That's all to say, this sounds like FUD but I think it should be taken seriously. Out of curiosity, where have you read this?

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#92
post #72

Earlier quoted context omitted.

Obligatory request to provide a source to backup some serious claims?

If you're a signal user and didn't know about this already, that should tell you everything you need to know about signal. See https://community.signalusers.org/t/proper-secure-value-secu... Then read the first line of their terms and privacy policy page which says: "Signal is designed to never collect or store any sensitive information." ( https://signal.org/legal/ ) Signal loves to brag about the times when the gov…

Sounds quite fishy :( . Any specific proofs in addition to all what have been said so far? I've checked the links, they don't really prove anything...

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#93
post #91

Earlier quoted context omitted.

[flagged]

I'm a big signal user yet skeptical that it's not directly involved with intelligence agencies. That's all to say, this sounds like FUD but I think it should be taken seriously. Out of curiosity, where have you read this?

It was a bit of a controversy when the change happened:

see https://web.archive.org/web/20210109010728/https://community...

https://www.vice.com/en/article/pkyzek/signal-new-pin-featur...

Note that the "solution" of disabling pins mentioned at the end of the article was later shown to not prevent the collection and storage of user data. It was just giving users a false sense of security. To this day there is no way to opt out of the data collection.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#94
post #83

Earlier quoted context omitted.

If you're a signal user and didn't know about this already, that should tell you everything you need to know about signal. See https://community.signalusers.org/t/proper-secure-value-secu... Then read the first line of their terms and privacy policy page which says: "Signal is designed to never collect or store any sensitive information." ( https://signal.org/legal/ ) Signal loves to brag about the times when the gov…

Also signals spam folder isn't open source on server side. They literally have code that reads your messages and checks if spam or not and you cant see what it does or how it's written. Couple this with signal being the preferred messaging app for 5 eyes countries as advised by their 3 letter agencies and well if you think those agencies are going to be advising a comms form they can't track, trace or read you obviou…

While it seems to be true that it’s not open-source, they claim (in strong terms) that they use techniques other than reading the message to make that assessment:

https://signal.org/blog/keeping-spam-off-signal/

They point out that the protocol’s end-to-end cryptographic guarantees are still open and in place, and verifiable as ever. As far as I can tell, they claim that they combine voluntary user spam reports and metadata signals of some sort:

> When a user clicks “Report Spam and Block”, their device sends only the phone number that initiated the conversation and a one-time anonymous message ID to the server. When accounts are repeatedly reported as spam or network traffic appears to be automated, we can issue “proof of humanity” checks to suspicious senders so they can’t send more messages until they’ve completed a challenge. For example, if you exceed a configured server-side threshold for making requests to Signal, you may need to complete a CAPTCHA within the Signal application before making more requests. This approach slows down spammers while allowing regular messages to continue to flow.

Does that seem unreasonable? Am I missing places where people have identified flaws in the protocol?

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#95
post #92

Earlier quoted context omitted.

If you're a signal user and didn't know about this already, that should tell you everything you need to know about signal. See https://community.signalusers.org/t/proper-secure-value-secu... Then read the first line of their terms and privacy policy page which says: "Signal is designed to never collect or store any sensitive information." ( https://signal.org/legal/ ) Signal loves to brag about the times when the gov…

Sounds quite fishy :( . Any specific proofs in addition to all what have been said so far? I've checked the links, they don't really prove anything...

here are links to additional discussions from the time of the change: https://community.signalusers.org/t/mandatory-pin-is-signal-...

One of the few articles that talked about it at the time: https://www.vice.com/en/article/pkyzek/signal-new-pin-featur...

One of the many reddit posts by confused users who misunderstood the very unclear communications by Signal: https://old.reddit.com/r/signal/comments/htmzrr/psa_disablin...

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#96
post #83

Earlier quoted context omitted.

If you're a signal user and didn't know about this already, that should tell you everything you need to know about signal. See https://community.signalusers.org/t/proper-secure-value-secu... Then read the first line of their terms and privacy policy page which says: "Signal is designed to never collect or store any sensitive information." ( https://signal.org/legal/ ) Signal loves to brag about the times when the gov…

Also signals spam folder isn't open source on server side. They literally have code that reads your messages and checks if spam or not and you cant see what it does or how it's written. Couple this with signal being the preferred messaging app for 5 eyes countries as advised by their 3 letter agencies and well if you think those agencies are going to be advising a comms form they can't track, trace or read you obviou…

[deleted]

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#97
They provided some domains, but not all of them are taken. For example, signal-protect[.]host is available, kropyva[.]site is available, signal-confirm[.]site is registered in Ukraine. Some of them are registered in Russia.

Never trust a country at war—any side. Party A blames B, Party B blames A, but both have their own agenda.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#98

I'd love to have more of my socializing happening on Signal. Anyone got a good way to convince the non-paranoid to use it?

I've had good luck just asking for it, even with group chats (though admittedly my friends are mostly technical and more privacy conscious than the average person). Usually it's a switch from FB Messenger and I just say that I don't want to be locked into Facebook anymore.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#99
post #90

Earlier quoted context omitted.

If you're a signal user and didn't know about this already, that should tell you everything you need to know about signal. See https://community.signalusers.org/t/proper-secure-value-secu... Then read the first line of their terms and privacy policy page which says: "Signal is designed to never collect or store any sensitive information." ( https://signal.org/legal/ ) Signal loves to brag about the times when the gov…

I see a link to a forum where an anonymous participant says “Since a recent version of Signal data of all Signal users is uploaded to Signal’s servers. This includes your profile name and photo, and a list of all your Signal-contacts.” They then link to a Signal blog (2019) explaining technical measures they were testing to provide verifiably tamperproof remote storage. https://signal.org/blog/secure-value-recovery/…

The communication Signal put out was extremely confusing and unclear which caused a lot of issues. They avoided answering questions about the data being collected and instead focused everything on SVR (see https://old.reddit.com/r/signal/comments/htmzrr/psa_disablin...)

The problems with the security of Signal's new data collection scheme was talked about at the time:

https://web.archive.org/web/20210126201848mp_/https://palant...

https://www.vice.com/en/article/pkyzek/signal-new-pin-featur...

You'll have to decide for yourself how secure pins and enclaves are, but even if you thought they were able to provide near-perfect security I would argue that outright lying to highly vulnerable users by saying "Signal is designed to never collect or store any sensitive information." on line one of their privacy policy page is inexcusable and not something you should tolerate in an application that depends on trust.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#100

Earlier quoted context omitted.

Just explain what end to end encryption means. People are starting to get it and don’t want companies able to read their messages.

My Signal experience: ex gf in college asks what app I’m using to text. Tell her it’s Signal, E2EE, messages are only stored on her phone and nobody else can read them. She says cool and downloads the app. Four months later her phone breaks. “Hey subjectsigma I got my new phone today. Where are all my messages?” “… Do you have your old phone? That’s the only place they are.” “No? Last time I got a new phone WhatsApp…

It only works for WhatsApp if you have Backup to Google activated[1]. I once tried to work with backuped files from my old phone and it didn't work. (Older tutorials indicated that it once worked, though.)

[1] There was a time WhatsApp had a nag-screen if you hadn't Backup to Google activated. So I guess most people would have eventually caved.

Post reply on HN